Impact
The Hide My WP Ghost plugin contains an SSRF flaw that allows an attacker to coerce the plugin into sending HTTP requests to arbitrary destinations. This can lead to exposure of sensitive internal resources, retrieval of restricted data, or commutation of further attacks against the host system. The weakness is characterized by CWE‑918 and is considered a medium‑high risk vulnerability.
Affected Systems
WordPress sites utilizing the Hide My WP Ghost plugin from any pre‑7.0.10 release. The flaw exists in all versions up to and including 7.0.09. Site administrators should verify the installed plugin version and determine if it falls within the affected range.
Risk and Exploitability
The CVSS score of 7.2 indicates a Moderate to High severity. The EPSS score is not available, so the current exploitation probability cannot be quantified, but the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, via HTTP requests that the plugin accepts. If exploited, an attacker could use the SSRF to enumerate internal services or exfiltrate data, potentially creating a foothold for additional compromises.
OpenCVE Enrichment